Agent skill

Glean Incident Runbook

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Triage: Is search returning results?. An agent skill from jeremylongshore/tons-of-skills-marketplace.

MITAuto-check passedDevOps & Cloud

Install Glean Incident Runbook

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-incident-runbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace glean-incident-runbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/glean-incident-runbook .claude/skills/glean-incident-runbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
glean-incident-runbook
GitHub stars
2.8k
Token cost
~1.7k tokens
SKILL.md length
695 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Triage: Is search returning results?. An agent skill from jeremylongshore/tons-of-skills-marketplace.

  • Works in 5 steps: Confirm outage with diagnostic curl… → Verify your Glean instance URL resolves… → Test from multiple networks to rule out… → …
  • Tasks that involve Runbooks and postmortems
  • SKILL.md covers Overview, Severity Levels, Diagnostic Steps and Incident Playbooks, plus 9 more sections
  • Calls curl and jq; needs GLEAN_API_TOKEN

What it does

Glean Incident Runbook is an agent skill from jeremylongshore/tons-of-skills-marketplace. Triage: Is search returning results? Check Glean status page. Trigger: "glean incident runbook", "incident-runbook".

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud, covering Runbooks and postmortems. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Tasks that involve Runbooks and postmortems

Example prompts

  • “glean incident runbook”
  • “incident-runbook”
  • “/glean-incident-runbook”

Requirements

  • A credential in GLEAN_API_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Confirm outage with diagnostic curl above and check Glean status page
  2. Verify your Glean instance URL resolves and TLS cert is valid
  3. Test from multiple networks to rule out local DNS or firewall issues
  4. Notify users that search is temporarily unavailable
  5. Contact Glean support with instance name, timestamps, and error codes

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npm:*)
    • Bash(curl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.glean.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GLEAN_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Glean Incident Runbook loads about 1.7k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 695 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 695 words, ~1,720 tokens.

Download SKILL.mdSave it as .claude/skills/glean-incident-runbook/SKILL.md (or your agent's skills folder).
name
glean-incident-runbook
description
Triage: Is search returning results? Check Glean status page. Trigger: "glean incident runbook", "incident-runbook".
allowed-tools
Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep
compatibility
Designed for Claude Code
version
1.8.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, enterprise-search, glean

Glean Incident Runbook

Overview

Incident response procedures for Glean enterprise search integration failures. Covers search degradation, connector sync failures, indexing backlogs, and permission sync drift. Glean aggregates knowledge across all company tools, so incidents impact employee productivity across the entire organization. When search breaks or returns stale results, teams lose access to critical institutional knowledge. Classify severity immediately and follow the matching playbook below.

Severity Levels

LevelDefinitionResponse TimeExample
P1 - CriticalSearch fully down or returning zero results15 minAll queries return empty, API 5xx errors
P2 - HighConnector sync failed, content going stale30 minGoogle Drive connector last synced 24h ago
P3 - MediumIndexing backlog or partial result degradation2 hoursNew documents not appearing for 4+ hours
P4 - LowPermission sync drift or single datasource issue8 hoursOne user sees docs they shouldn't access

Diagnostic Steps

bash
# Test search API health
curl -s -o /dev/null -w "HTTP %{http_code}\n" \
  -H "Authorization: Bearer $GLEAN_API_TOKEN" \
  -H "Content-Type: application/json" \
  -X POST https://your-domain.glean.com/api/v1/search \
  -d '{"query": "test", "pageSize": 1}'

# Check datasource connector status
curl -s -H "Authorization: Bearer $GLEAN_API_TOKEN" \
  https://your-domain.glean.com/api/v1/getdatasourceconfig \
  -d '{"datasource": "DATASOURCE_NAME"}' | jq '.status'

# Verify indexing queue depth
curl -s -H "Authorization: Bearer $GLEAN_API_TOKEN" \
  https://your-domain.glean.com/api/index/v1/getstatus | jq '.statistics'

Incident Playbooks

API Outage
  1. Confirm outage with diagnostic curl above and check Glean status page
  2. Verify your Glean instance URL resolves and TLS cert is valid
  3. Test from multiple networks to rule out local DNS or firewall issues
  4. Notify users that search is temporarily unavailable
  5. Contact Glean support with instance name, timestamps, and error codes
Authentication Failure
  1. Verify API token is set: echo $GLEAN_API_TOKEN | wc -c
  2. Check token expiry — Glean tokens may have a TTL configured by your admin
  3. Test with a minimal search request (see diagnostics above)
  4. If 401: regenerate token in Glean admin console under API settings
  5. If 403: verify token scopes include search and indexing permissions
Data Sync Failure
  1. Identify which connector failed via getdatasourceconfig for each source
  2. Check connector credentials — OAuth tokens for Google/Slack/Confluence may have expired
  3. Review connector error logs in Glean admin under Datasource Management
  4. Re-authorize the connector if credentials expired
  5. Trigger a manual re-crawl for the affected datasource
  6. Monitor indexing status until backlog clears

Communication Template

markdown
**Incident**: Glean Search [Outage/Degradation]
**Status**: [Investigating/Identified/Mitigating/Resolved]
**Started**: YYYY-MM-DD HH:MM UTC
**Impact**: [Search unavailable / results stale since HH:MM / N datasources not syncing]
**Current action**: [Connector re-auth in progress / Glean support engaged / manual re-crawl running]
**Next update**: HH:MM UTC

Post-Incident

  • Document timeline from detection to resolution
  • Identify root cause (connector auth expiry / Glean platform issue / indexing bottleneck)
  • Audit all connector credentials for upcoming expirations
  • Verify permission sync is accurate post-recovery
  • Add alerting for connector sync age thresholds
  • Schedule review of datasource health dashboard weekly

Error Handling

Incident TypeDetectionResolution
Search degradationEmpty results or low relevance scoresCheck API health, verify index freshness
Connector sync failureStale content, getdatasourceconfig shows errorRe-authorize connector, trigger manual crawl
Indexing backlogNew docs not searchable after 4+ hoursMonitor queue depth, contact Glean if persistent
Permission sync driftUsers see restricted docs or miss accessible onesAudit datasource permissions, trigger permission re-sync
Show full SKILL.md (262 more words)Show less

Prerequisites

  • An incident owner, an approved support path, and a synthetic probe query that reveals no customer or employee content.
  • Read-only diagnostic credentials scoped to the affected staging or production datasource; never paste tokens, queries, document titles, or result snippets into incident chat.
  • A known-good baseline for connector freshness, permission-sync age, and the change window that preceded the incident.

Instructions

  1. Open a timestamped incident record and classify impact using the severity table; preserve only error codes and aggregate counts.
  2. Run the synthetic health probe, then isolate the failing boundary: identity, search endpoint, source connector, index backlog, or ACL synchronization.
  3. Freeze nonessential connector configuration changes while the owner compares the affected source's ACL watermark with the source system.
  4. Apply the smallest reversible remediation (for example, reauthorize one connector or queue a scoped resync), observe the synthetic probe and freshness metrics, and stop if access expands unexpectedly.
  5. Close only after a second, least-privilege test identity receives the expected allow and deny outcomes. Record the rollback used or explicitly record that no change was made.

Output

Produce an incident receipt containing the severity, UTC start and resolution times, affected datasource identifiers, redacted error codes, remediation and rollback decision, and the two synthetic authorization outcomes. Keep raw search results, user identifiers, and document content out of the receipt.

Examples

For a stale staging-handbook connector, record: P2; source=staging-handbook; sync_age=6h; action=scoped_reauthorize; probe=healthy; allow_test=pass; deny_test=pass. This proves recovery without exposing a real query or document.

Resources

Next Steps

See glean-observability for monitoring setup and connector health dashboards.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/glean-incident-runbook of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Glean Incident Runbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Glean Incident Runbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Glean Incident Runbook this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
Trader Memory Coretradermonty/claude-trading-skills3k2 repos~4.3kAutomated safety check: PassMIT
Author Migrationnrwl/nx29k—~12kAutomated safety check: NotesMIT
Write Notes Like Deepseekczm15053/write-notes-like-deepseek508—~2kAutomated safety check: PassNone
OpenRig Upgrade Proceduremvschwarz/openrig6.8k—~2.9kAutomated safety check: PassApache-2.0
GreptimeDB Release RunbookGreptimeTeam/greptimedb6.7k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Trader Memory Core

    tradermonty/claude-trading-skills

    Track investment theses across their lifecycle — from screening idea to closed position with postmortem.

    3k GitHub starsUsed in 2 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Author or scope a first-party Nx migration. An agent skill from nrwl/nx.

    29k GitHub stars~12k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Write Notes Like Deepseek

    czm15053/write-notes-like-deepseek

    A skill your agent uses when a change is non-trivial by DSH standards (behavior, architecture, cross-file contracts, process/tooling, testing strategy, or on-disk/wire/config formats), when choosing…

    508 GitHub stars~2k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • OpenRig Upgrade Procedure

    mvschwarz/openrig

    Walks an agent through upgrading the OpenRig CLI and daemon one observed step at a time, keeping live seats alive and reconciling managed plugin files.

    6.8k GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GreptimeDB Release Runbook

    GreptimeTeam/greptimedb

    Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.

    6.7k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Statem

    henryqin1997/statem

    A skill your agent uses when a long coding or research task should be managed with statem state-machine runbooks, including creating specs, starting or resuming runs, checking current state…

    1.3k GitHub stars~1.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Glean Incident Runbook

What does Glean Incident Runbook do?

Triage: Is search returning results?. An agent skill from jeremylongshore/tons-of-skills-marketplace. Glean Incident Runbook is an agent skill from jeremylongshore/tons-of-skills-marketplace. Triage: Is search returning results?

When should I use Glean Incident Runbook?

Glean Incident Runbook fits situations like: tasks that involve Runbooks and postmortems.

How do I install Glean Incident Runbook in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-incident-runbook -a claude-code`. Or copy the skill folder (skills/.curated/glean-incident-runbook in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/glean-incident-runbook in your project. Claude Code loads it when a task matches its description.

How do I install Glean Incident Runbook in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-incident-runbook -a codex`. Or copy the skill folder (skills/.curated/glean-incident-runbook in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/glean-incident-runbook in your project. Codex loads it when a task matches its description.

Can I use Glean Incident Runbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-incident-runbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/glean-incident-runbook, .gemini/skills/glean-incident-runbook, .github/skills/glean-incident-runbook and .opencode/skills/glean-incident-runbook in your project.

What does Glean Incident Runbook need to run?

Going by SKILL.md and its folder, Glean Incident Runbook needs the command-line tools its instructions call (curl and jq) and credentials named GLEAN_API_TOKEN. Our summary lists: A credential in GLEAN_API_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Glean Incident Runbook access the network?

SKILL.md names 1 domain. As links in the text: developers.glean.com. This is read from the text; nothing was executed.

Is Glean Incident Runbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Glean Incident Runbook use?

Glean Incident Runbook is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Glean Incident Runbook use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Glean Incident Runbook?

Skills that share tags, products or a category with Glean Incident Runbook: Trader Memory Core (tradermonty/claude-trading-skills, 3k stars), Author Migration (nrwl/nx, 29k stars), Write Notes Like Deepseek (czm15053/write-notes-like-deepseek, 508 stars) and OpenRig Upgrade Procedure (mvschwarz/openrig, 6.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Glean Incident Runbook?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.